Access Token Manipulation - runas savecred, PS Impersonation APIs, Token Tools

Detects signs of access token manipulation and impersonation, including the use of 'runas' with saved credentials, suspicious PowerShell API calls for identity management, usage of known token-manipulation tools (e.g., incognito), and reconnaissance using 'whoami /priv'. These activities are indicative of privilege escalation attempts or lateral movement.